pg_partman 是一个用于管理按时间或 ID 划分的分区表的 PostgreSQL 扩展。在 5.5.0 版本之前,如果安装了 pg_jobmon 并且 为 ,pg_partman 中多个函数的异常处理逻辑会将 参数原样嵌入到一个 SQL 字符串字面量中,用于调用 。攻击者若拥有 权限,可以创建一个包含单引号的父表名,从而终止该字面量并注入 SQL 语句;当触发受影响的异常处理路径时,注入的 SQL 就会被执行。如果 (pg_partman 后台工作进程)到达该代码路径,注入的 SQL 将以 的特权执行,而该
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| pgpartman | pg_partman | < 5.5.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| pgpartman | pg_partman | < 5.5.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-61781 | 9.9 CRITICAL | pg_partman has privilege escalation through SQL injection in create_partition_time() |
| CVE-2026-61820 | 8.5 HIGH | pg_partman privilege escalation via SQL injection when inheriting template properties |
| CVE-2026-61817 | 8.5 HIGH | pg_partman privilege escalation via SQL injection in several functions via time decoder |
| CVE-2026-61818 | 8.5 HIGH | pg_partman SQL injection in undo partition time encoder |
| CVE-2026-61821 | 8.5 HIGH | pg_partman authorization bypass to move child tables between schemas during retention |
| CVE-2026-61822 | 6.5 MEDIUM | pg_partman disable maintenance for all partition sets |
No comments yet